CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2025-7732

    Last Modified: 21 Apr 2026

    The Lazy Load for Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lazy‑loading handlers in all versions up to, and including, 2.18.7 due to insufficient input sanitization and output escaping. The plugin’s JavaScript registration handlers read the client‑supplied 'data-video-title' and 'href' attributes, decode HTML entities by default, and pass them directly into DOM sinks without any escaping or validation. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 27 Aug 2025
    5.8
    Medium

    CVE-2025-56694

    Last Modified: 9 Sept 2025

    Client-side password validation (CWE-602) in lumasoft fotoShare Cloud 2025-03-13 allowing unauthenticated attackers to view password-protected photo albums.

    Published: 27 Aug 2025
    6.5
    Medium

    CVE-2025-55495

    Last Modified: 3 Sept 2025

    Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function.

    Published: 27 Aug 2025
    9.8
    Critical

    CVE-2025-50428

    Last Modified: 9 Sept 2025

    In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user input passed via the interface parameter.

    Published: 27 Aug 2025
    9.8
    Critical

    CVE-2025-50972

    Last Modified: 8 Sept 2025

    SQL Injection vulnerability in AbanteCart 1.4.2, allows unauthenticated attackers to execute arbitrary SQL commands via the tmpl_id parameter to index.php. Three techniques have been demonstrated: error-based injection using a crafted FLOOR-based payload, time-based blind injection via SLEEP(), and UNION-based injection to extract arbitrary data.

    Published: 27 Aug 2025
    6.1
    Medium

    CVE-2025-50978

    Last Modified: 9 Sept 2025

    In Gitblit v1.7.1, a reflected cross-site scripting (XSS) vulnerability exists in the way repository path names are handled. By injecting a specially crafted path payload an attacker can cause arbitrary JavaScript to execute when a victim views the manipulated URL. This flaw stems from insufficient input sanitization of filename elements.

    Published: 27 Aug 2025
    5.6
    Medium

    CVE-2025-50986

    Last Modified: 9 Sept 2025

    diskover-web v2.3.0 Community Edition suffers from multiple stored cross-site scripting (XSS) vulnerabilities in its administrative settings interface. Various configuration fields such as ES_HOST, ES_INDEXREFRESH, ES_PORT, ES_SCROLLSIZE, ES_TRANSLOGSIZE, ES_TRANSLOGSYNCINT, EXCLUDES_FILES, FILE_TYPES[], INCLUDES_DIRS, INCLUDES_FILES, and TIMEZONE do not properly sanitize user-supplied input. Malicious payloads submitted via these parameters are persisted in the application and executed whenever an administrator views or edits the settings page.

    Published: 27 Aug 2025
    7
    High

    CVE-2025-51667

    Last Modified: 9 Sept 2025

    An issue was discovered in simple-admin-core v1.2.0 thru v1.6.7. The /sys-api/role/update interface in the simple-admin-core system has a limited SQL injection vulnerability, which may lead to partial data leakage or disruption of normal system operations.

    Published: 27 Aug 2025
    6.6
    Medium

    CVE-2025-55582

    Last Modified: 9 Sept 2025

    D-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly respawns binaries such as `dcp` and `signalc` without verifying integrity, authenticity, or permissions. An attacker with local filesystem access (via physical access, firmware modification, or debug interfaces) can replace these binaries with malicious payloads. The script executes these binaries as root in an infinite loop, leading to persistent privilege escalation and arbitrary code execution. This issue is mitigated in v1.09.02, but the product is officially End-of-Life and unsupported.

    Published: 27 Aug 2025
    8.8
    High

    CVE-2024-37777

    Last Modified: 9 Sept 2025

    O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function.

    Published: 27 Aug 2025
    7.3
    High

    CVE-2025-55618

    Last Modified: 6 Apr 2026

    In Hyundai Navigation App STD5W.EUR.HMC.230516.afa908d, an attacker can inject HTML payloads in the profile name field in navigation app which then get rendered.

    Published: 27 Aug 2025
    6.1
    Medium

    CVE-2025-50977

    Last Modified: 9 Sept 2025

    A template injection vulnerability leading to reflected cross-site scripting (XSS) has been identified in version 1.7.1, requiring authenticated admin access for exploitation. The vulnerability exists in the 'r' parameter and allows attackers to inject malicious Angular expressions that execute JavaScript code in the context of the application. The flaw can be exploited through GET requests to the summary endpoint as well as POST requests to specific Wicket interface endpoints, though the GET method provides easier weaponization. This vulnerability enables authenticated administrators to execute arbitrary client-side code, potentially leading to session hijacking, data theft, or further privilege escalation attacks.

    Published: 27 Aug 2025
    8.6
    High

    CVE-2025-50979

    Last Modified: 9 Sept 2025

    NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The search query parameter is not properly sanitized, allowing unauthenticated, remote attackers to inject boolean-based blind and PostgreSQL error-based payloads.

    Published: 27 Aug 2025
    8.3
    High

    CVE-2025-50983

    Last Modified: 9 Sept 2025

    SQL Injection vulnerability exists in the sortKey parameter of the GET /api/v1/wanted/cutoff API endpoint in readarr 0.4.15.2787. The endpoint fails to properly sanitize user-supplied input, allowing attackers to inject and execute arbitrary SQL commands against the backend SQLite database. Sqlmap confirmed exploitation via stacked queries, demonstrating that the parameter can be abused to run arbitrary SQL statements. A heavy query was executed using SQLite's RANDOMBLOB() and HEX() functions to simulate a time-based payload, indicating deep control over database interactions.

    Published: 27 Aug 2025
    5.3
    Medium

    CVE-2025-50984

    Last Modified: 9 Sept 2025

    diskover-web v2.3.0 Community Edition is vulnerable to multiple boolean-based blind SQL injection flaws in its Elasticsearch configuration form. Unsanitized user input in POST parameters such as ES_PASS, ES_MAXSIZE, ES_TRANSLOGSIZE, ES_TIMEOUT, ES_USER, ES_HOST, ES_PORT, ES_SCROLLSIZE, ES_CHUNKSIZE and others can be crafted to inject arbitrary SQLite expressions wrapped in JSON functions. By exploiting these injection points, an attacker can infer or extract sensitive information from the underlying database without authentication. This issue stems from improper input validation and parameterization in the application's JSON-based query construction.

    Published: 27 Aug 2025
    5.6
    Medium

    CVE-2025-50985

    Last Modified: 9 Sept 2025

    diskover-web v2.3.0 Community Edition is vulnerable to multiple reflected cross-site scripting (XSS) flaws in its web interface. Unsanitized GET parameters including maxage, maxindex, index, path, q (query), and doctype are directly echoed into the HTML response, allowing attackers to inject and execute arbitrary JavaScript when a victim visits a maliciously crafted URL.

    Published: 27 Aug 2025
    9.1
    Critical

    CVE-2025-50989

    Last Modified: 26 Sept 2025

    OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). The span POST parameter is concatenated into a system-level command without proper sanitization or escaping, allowing an administrator to inject arbitrary shell operators and payloads. Successful exploitation results in remote code execution with the privileges of the web service (typically root), potentially leading to full system compromise or lateral movement. This vulnerability arises from inadequate input validation and improper handling of user-supplied data in backend command invocations.

    Published: 27 Aug 2025
    9.8
    Critical

    CVE-2025-52122

    Last Modified: 9 Sept 2025

    Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).

    Published: 27 Aug 2025
    6.5
    Medium

    CVE-2025-54598

    Last Modified: 9 Sept 2025

    The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows CSRF to delete all notifications via the /notifications/delete/ URI.

    Published: 27 Aug 2025
    8.8
    High

    CVE-2025-55422

    Last Modified: 9 Sept 2025

    In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus.

    Published: 27 Aug 2025
    4.4
    Medium

    CVE-2025-8490

    Last Modified: 21 Apr 2026

    The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Import in all versions up to, and including, 7.97 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 26 Aug 2025
    4
    Medium

    CVE-2025-26417

    Last Modified: 2 Sept 2025

    In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening files in shared storage due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    4
    Medium

    CVE-2025-22413

    Last Modified: 2 Sept 2025

    In multiple functions of hyp-main.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    8.8
    High

    CVE-2025-22412

    Last Modified: 26 Feb 2026

    In multiple functions of sdp_server.cc, there is a possible use after free due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    8.8
    High

    CVE-2025-22411

    Last Modified: 26 Feb 2026

    In process_service_attr_rsp of sdp_discovery.cc, there is a possible use after free due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    8.4
    High

    CVE-2025-22410

    Last Modified: 2 Sept 2025

    In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    8.4
    High

    CVE-2025-22409

    Last Modified: 26 Feb 2026

    In rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    9.8
    Critical

    CVE-2025-22408

    Last Modified: 2 Sept 2025

    In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    5.5
    Medium

    CVE-2025-22407

    Last Modified: 2 Sept 2025

    In hidd_check_config_done of hidd_conn.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    8.4
    High

    CVE-2025-22406

    Last Modified: 2 Sept 2025

    In bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    8.4
    High

    CVE-2025-22405

    Last Modified: 2 Sept 2025

    In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    8.4
    High

    CVE-2025-22404

    Last Modified: 2 Sept 2025

    In avct_lcb_msg_ind of avct_lcb_act.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    9.8
    Critical

    CVE-2025-22403

    Last Modified: 2 Sept 2025

    In sdp_snd_service_search_req of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    7.5
    High

    CVE-2025-0093

    Last Modified: 2 Sept 2025

    In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 26 Aug 2025
    6.5
    Medium

    CVE-2025-0092

    Last Modified: 2 Sept 2025

    In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misleading or insufficient UI. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 26 Aug 2025
    6.2
    Medium

    CVE-2025-0086

    Last Modified: 2 Sept 2025

    In onResult of AccountManagerService.java, there is a possible way to overwrite auth token due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    8.8
    High

    CVE-2025-0084

    Last Modified: 2 Sept 2025

    In multiple locations, there is a possible out of bounds write due to a use after free. This could lead to remote code execution over Bluetooth, if HFP support is enabled, with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    4
    Medium

    CVE-2025-0083

    Last Modified: 2 Sept 2025

    In multiple locations, there is a possible way to access content across user profiles due to URI double encoding. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    5.5
    Medium

    CVE-2025-0082

    Last Modified: 2 Sept 2025

    In multiple functions of StatusHint.java and TelecomServiceImpl.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 26 Aug 2025
    7.5
    High

    CVE-2025-0081

    Last Modified: 2 Sept 2025

    In dng_lossless_decoder::HuffDecode of dng_lossless_jpeg.cpp, there is a possible way to cause a crash due to uninitialized data. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    7.8
    High

    CVE-2025-0080

    Last Modified: 2 Sept 2025

    In multiple locations, there is a possible way to overlay the installation confirmation dialog due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    7.8
    High

    CVE-2025-0079

    Last Modified: 2 Sept 2025

    In multiple locations, there is a possible way that avdtp and avctp channels could be unencrypted due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    8.8
    High

    CVE-2025-0078

    Last Modified: 2 Sept 2025

    In main of main.cpp, there is a possible way to bypass SELinux due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    9.8
    Critical

    CVE-2025-0075

    Last Modified: 2 Sept 2025

    In process_service_search_attr_req of sdp_server.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    9.8
    Critical

    CVE-2025-0074

    Last Modified: 2 Sept 2025

    In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    5.5
    Medium

    CVE-2024-49740

    Last Modified: 2 Sept 2025

    In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    8
    High

    CVE-2023-21125

    Last Modified: 2 Sept 2025

    In btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 26 Aug 2025
    7.9
    High

    CVE-2025-57820

    Last Modified: 15 Apr 2026

    Svelte devalue is a utility library. Prior to version 5.3.2, a string passed to devalue.parse could represent an object with a __proto__ property and devalue.parse does not check that an index is numeric. This could result in assigning prototypes to objects and properties, leading to prototype pollution. This issue has been fixed in version 5.3.2

    Published: 26 Aug 2025
    6.4
    Medium

    CVE-2025-9277

    Last Modified: 20 Apr 2026

    The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the broken preg_replace expression in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 26 Aug 2025
    5.1
    Medium

    CVE-2025-35112

    Last Modified: 2 Sept 2025

    Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an authenticated attacker to import the template file and perform path traversal on the local system files. Users should upgrade to Agiloft Release 31.

    Published: 26 Aug 2025